Showing posts with label virtual; IEC 61850; MMS; digital twin. Show all posts
Showing posts with label virtual; IEC 61850; MMS; digital twin. Show all posts

Monday, December 15, 2025

NEW version of the Famous Whitepaper Requirements for Secure Control and Telecommunication Systems

The Austrian, German, and Swiss Utilities have published (with the support of Dr. Stephan Beirer and Marl Joos (GAI NetConsult GmbH, Berlin/Germany)) the Version 3.0 of the famous 

Whitepaper Requirements for Secure Control and Telecommunication Systems

The English version (pdf, 88 pages) could be downloaded HERE.

Die deutsche Version (pdf, 92 Seiten) kann HIER heruntergeladen werden.

It is highly recommended to read, understand, and implement the recommendations! They reflect the latest experiences and need in our highly interconnected electric power world!

Today I will focus on two issues: the first is discussed in the Whitepaper, the second is discussed in a paper from AXPRO in Switzerland.

The Whitepaper says on page 46 (bzw Seite 47 in der deutschen Version):

"In line with the given technical capabilities, standardised IEC protocols should be used across the board. The private range of these communication protocols should only be used where necessary for technological reasons. Without additional measures, the standard protocols IEC 60870-5-101/104 and IEC 61850 offer no secure integrity protection, authentication or encryption. In such cases, the available extensions according to IEC 62351 should be used. Potential limitations, e.g. in terms of performance and error diagnostics as well as the necessary key management infrastructure and processes should be considered.

For communication across zone boundaries, protocol breaks should be provided, e.g. through application layer gateways or by converting to a different protocol, to reduce potential vulnerabilities and weak points."

I fully agree with this last sentence. This brings me to the second issue: 

The Swiss utility AXPRO published a great paper with the title: OT-Security im Unterwerk  ... means in substations ... the paper is in English. You can download it HERE.

On page 3 you can find this:

Geräte diversifizieren

"Die klassischen Ansätze der Literatur geben einen Überblick über Lösungen. Dies beginnt bei gängigen Konzepten zur Ersatzteilhaltung und setzt sich bei der technischen Redundanz von Komponenten fort. Die zusätzlichen Komponenten halten den Betrieb bei einem Ausfall aufrecht – zumindest einen Minimalbetrieb. Die eingesetzten Geräte und Systeme können zudem mit unter-schiedlichen Komponenten diversifiziert werden, beispielsweise durch Geräte unterschiedlicher Hersteller, Gerätefamilien mit signifikanten Unterschieden sowie Kommunikationsvarianten. Eine einzelne Schwachstelle kann somit nie die Funktion des Gesamtsystems gefährden. Die Diversität stellt eine Hürde dar, die ein Angreifer überwinden muss. Allerdings muss auch beachtet und akzeptiert werden, dass durch eine grössere Diversität ein Mehraufwand für den Betrieb und somit zusätzliche Kosten entstehen."

They are obviously following the recommendation of the Whitepaper!! Thanks. The statement in the last sentence is important to understand: The implementation and application of many security measures needs peopleware and reasonable budgets!

I have discussed peopleware many times for years ... it seems to be more important than ever ... see also my latest discussion on people ...

Be aware: The most secure communication is the one that is not implemented or implemented but not in use!



Monday, February 12, 2024

Global Push for IEC 61850 - The vPAC Alliance for Virtual Protection Automation and Control

IEC 61850 is one of the crucial core components of the architecture of the Virtual Protection Automation and Control (vPAC) Alliance: "Driving standards-based, open, interoperable, and secure software-defined architecture to host protection, automation, and control solutions for power system substations." 

As of the membership list I accessed today 23 well known companies are involved in the alliance: ABB, Advantec, AEP, Black&Veatch, Crystal, Dell Technologies, ... SCE, ... Intel, ... Omicron, Phoenix Contact, Schneider Electric, Siemens Energy, ... 

This kind of alliances will make a chance in how to protect, automate, control, and supervise power systems ... and other system where power is a crucial factor ... like in factories, buildings, ... airports, ...

"A key plays the "virtual protection relay (VPR) concept [pdf document] – an architecture where software defined and virtualized platforms are deployed to host the critical circuit protection functions for an advanced and agile grid. ... 

Standard models of various protection functions were devised for possible interoperability between protection IEDs from any vendor. Standards were prepared for data exchange between devices (station bus) and current/voltage information from field (process bus). Acceptance of the IEC 61850 standards worldwide have resulted in station level and process level communication networks for exchange of digitized raw values (using Sampled Values, or SV, protocol) and processed values/information across the substation devices and beyond the substation to centralized monitoring systems. ..."

It is interesting that it took some 40 years from the definition of Virtual Manufacturing Devices (VMD) in ISO 9506 (MMS, Manufacturing Message Specification) until such a big alliance has the term "virtual" in its name! I have demonstrated on and on since the 80s that this is the future ... 

MMS defines Virtual Manufacturing Devices in clause 6 of part ISO 9506-1 as follows:

I have found in the automation domain that only a few engineers understand abstraction and virtualization. The following wise saying may help ... try it:

If it's there and you can see it It's REAL
If it's there and you can't see it It's TRANSPARENT
If it's not there and you can see it It's VIRTUAL
If it's not there and you can't see it It's GONE
Roy Wills

IEC 61850, IEC 61400-25 (Windpower), and IEC 60870-6 (TASE.2/ICCP) use MMS and the concepts of abstraction and virtualization ... I had a chance to describe these crucial basic concepts as editor of the first edition of IEC 61850-7-1 (Basic communication structure – Principles and models) ... here is what I have written ... some 20 years ago ... still in the current edition:

" ... The IEC 61850 series defines the information and information exchange in a way that it is independent of a concrete implementation (i.e., it uses abstract models). The standard also uses the concept of virtualisation. Virtualisation provides a view of those aspects of a real device that are of interest for the information exchange with other devices. Only those details that are required to provide interoperability of devices are defined in the IEC 61850 series. ..." 

I still like it.

It is great to see that this concept (defined in the 80s) is in the core of future protection, automation, and SCADA ... 

Let me know what you thing ... you find me on LinkedIn as well.

Good luck!


Friday, November 24, 2023

Some Impressions From The MATPOST Conference 2023 in Lyon (France)

Andrea Bonetti has posted some impression from the "Digital Twin" world demonstrated at the conference.
Click HERE for the brief report.
What is the difference of a digital device and its twin? In the IEC 61850 domain, a IED (Intelligent Electronic Device) hosts a virtual IED (the models, services, bridges to the applications, ... applications). The host may be a protection device or any other computer platform that can run the software. Why do we talk about twins? We could have triplets or even quadruplets of the same virtual device ... when we run the software on three or four or more platforms.
A digital twin is a digital twin of a digital twin ... the crucial term here is: Virtual Device - this is what an IED in IEC 61850 is!
An IED in the IEC 61850 world could be:
  1. A configuration of an IED section in an SCL document
  2. An IED section of an SCL document hosted, e.g., in a relay or any other controller
  3. A physical relay installed in a cabinet
Note that this virtualization was applied in MMS (Manufacturing Message Specification, ISO 9506) and used in IEC 61850-8-1. In MMS the virtual IED was named VMD - Virtual Manufacturing Device ... some 40 years ago ... hahaha ...
The following may help you to understand what virtual means:
If it's there and you can see it      It's REAL
If it's there and you can't see it    It's TRANSPARENT
If it's not there and you can see it      It's VIRTUAL
If it's not there and you can't see it      It's GONE
Roy Wills
Any question?